libxslt: Processing web content may disclose sensitive information
Published Sep 26, 2023
6.5
MEDIUMCVSS 3.1
EPSS 1.33%
Description
The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.6, tvOS 17, iOS 16.7 and iPadOS 16.7, macOS Monterey 12.7, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. Processing web content may disclose sensitive information.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<16.7
- Version unspecifiedStatusaffectedConstraints<17
- Version
-
- Version unspecifiedStatusaffectedConstraints<12.7
- Version unspecifiedStatusaffectedConstraints<13.6
- Version unspecifiedStatusaffectedConstraints<14
- Version
-
- Version unspecifiedStatusaffectedConstraints<17
- Version
-
- Version unspecifiedStatusaffectedConstraints<10
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Apple | iOS and iPadOS | n/a |
| ||||||||||||
| Apple | macOS | n/a |
| ||||||||||||
| Apple | tvOS | n/a |
| ||||||||||||
| Apple | watchOS | n/a |
|
No data.
Red Hat AI Inference Server 3.2
rhaiis/model-opt-cuda-rhel9:1780681984
Fixed · RHSA-2026:25096
Red Hat AI Inference Server 3.2
rhaiis/vllm-cuda-rhel9:1775740563
Fixed · RHSA-2026:7335
Red Hat AI Inference Server 3.3
rhaiis/model-opt-cuda-rhel9:1775749857
Fixed · RHSA-2026:8748
Red Hat AI Inference Server 3.3
rhaiis/model-opt-cuda-rhel9:1778244559
Fixed · RHSA-2026:16008
Red Hat AI Inference Server 3.3
rhaiis/vllm-cuda-rhel9:1775680192
Fixed · RHSA-2026:8746
Red Hat AI Inference Server 3.3
rhaiis/vllm-rocm-rhel9:1775680262
Fixed · RHSA-2026:8747
Red Hat AI Inference Server 3.3
rhaiis/vllm-rocm-rhel9:1778244531
Fixed · RHSA-2026:16009
Red Hat AI Inference Server 3.3
rhaiis/vllm-spyre-rhel9:1778244546
Fixed · RHSA-2026:16174
Red Hat Enterprise Linux 8
libxslt-0:1.1.32-6.2.el8_10
Fixed · RHSA-2025:8676
Red Hat Enterprise Linux 8
libxslt-0:1.1.32-6.2.el8_10
Fixed · RHSA-2025:8676
Red Hat Enterprise Linux 9
libxslt-0:1.1.34-14.el9_7.1
Fixed · RHSA-2026:6266
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
libxslt-0:1.1.34-12.el9_2
Fixed · RHSA-2026:29811
Red Hat Enterprise Linux 9.4 Extended Update Support
libxslt-0:1.1.34-14.el9_4
Fixed · RHSA-2025:9016
Red Hat Enterprise Linux 9.6 Extended Update Support
libxslt-0:1.1.34-13.el9_6.1
Fixed · RHSA-2026:6499
Red Hat Update Infrastructure 5
rhui5/rhua-rhel9:1776868842
Fixed · RHSA-2026:10065
Red Hat Enterprise Linux 10
libxslt
Not affected
Red Hat Enterprise Linux 6
libxslt
Out of support scope
Red Hat Enterprise Linux 7
libxslt
Out of support scope
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-9
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat AI Inference Server 3.2 | rhaiis/model-opt-cuda-rhel9:1780681984 | Fixed | RHSA-2026:25096 |
| Red Hat AI Inference Server 3.2 | rhaiis/vllm-cuda-rhel9:1775740563 | Fixed | RHSA-2026:7335 |
| Red Hat AI Inference Server 3.3 | rhaiis/model-opt-cuda-rhel9:1775749857 | Fixed | RHSA-2026:8748 |
| Red Hat AI Inference Server 3.3 | rhaiis/model-opt-cuda-rhel9:1778244559 | Fixed | RHSA-2026:16008 |
| Red Hat AI Inference Server 3.3 | rhaiis/vllm-cuda-rhel9:1775680192 | Fixed | RHSA-2026:8746 |
| Red Hat AI Inference Server 3.3 | rhaiis/vllm-rocm-rhel9:1775680262 | Fixed | RHSA-2026:8747 |
| Red Hat AI Inference Server 3.3 | rhaiis/vllm-rocm-rhel9:1778244531 | Fixed | RHSA-2026:16009 |
| Red Hat AI Inference Server 3.3 | rhaiis/vllm-spyre-rhel9:1778244546 | Fixed | RHSA-2026:16174 |
| Red Hat Enterprise Linux 8 | libxslt-0:1.1.32-6.2.el8_10 | Fixed | RHSA-2025:8676 |
| Red Hat Enterprise Linux 8 | libxslt-0:1.1.32-6.2.el8_10 | Fixed | RHSA-2025:8676 |
| Red Hat Enterprise Linux 9 | libxslt-0:1.1.34-14.el9_7.1 | Fixed | RHSA-2026:6266 |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | libxslt-0:1.1.34-12.el9_2 | Fixed | RHSA-2026:29811 |
| Red Hat Enterprise Linux 9.4 Extended Update Support | libxslt-0:1.1.34-14.el9_4 | Fixed | RHSA-2025:9016 |
| Red Hat Enterprise Linux 9.6 Extended Update Support | libxslt-0:1.1.34-13.el9_6.1 | Fixed | RHSA-2026:6499 |
| Red Hat Update Infrastructure 5 | rhui5/rhua-rhel9:1776868842 | Fixed | RHSA-2026:10065 |
| Red Hat Enterprise Linux 10 | libxslt | Not affected | n/a |
| Red Hat Enterprise Linux 6 | libxslt | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | libxslt | Out of support scope | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-9 | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This CVE is a duplicate of CVE-2022-4909.
References (28)
- http://seclists.org/fulldisclosure/2023/Oct/10 Mailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2023/Oct/3
- http://seclists.org/fulldisclosure/2023/Oct/4
- http://seclists.org/fulldisclosure/2023/Oct/5 Mailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2023/Oct/6
- http://seclists.org/fulldisclosure/2023/Oct/8
- http://seclists.org/fulldisclosure/2023/Oct/9
- https://access.redhat.com/security/cve/CVE-2023-40403 Vendor Advisory
- https://bugs.chromium.org/p/chromium/issues/detail?id=1356211
- https://bugzilla.gnome.org/show_bug.cgi?id=751621
- https://bugzilla.redhat.com/show_bug.cgi?id=2349766 Issue Tracking
- https://gitlab.gnome.org/GNOME/libxslt/-/issues/94
- https://lists.debian.org/debian-lts-announce/2025/09/msg00024.html
- https://nvd.nist.gov/vuln/detail/CVE-2023-40403
- https://support.apple.com/en-us/HT213927 Release NotesVendor Advisory
- https://support.apple.com/en-us/HT213931 Release NotesVendor Advisory
- https://support.apple.com/en-us/HT213932 Release NotesVendor Advisory
- https://support.apple.com/en-us/HT213936 Release NotesVendor Advisory
- https://support.apple.com/en-us/HT213937 Release NotesVendor Advisory
- https://support.apple.com/en-us/HT213938 Release NotesVendor Advisory
- https://support.apple.com/en-us/HT213940 Release NotesVendor Advisory
- https://support.apple.com/kb/HT213931
- https://support.apple.com/kb/HT213932
- https://support.apple.com/kb/HT213936
- https://support.apple.com/kb/HT213937
- https://support.apple.com/kb/HT213938
- https://support.apple.com/kb/HT213940
- https://www.cve.org/CVERecord?id=CVE-2023-40403
Change history (0)
No recorded changes yet.